Commit graph

4966 commits

Author SHA1 Message Date
pulse-triage[bot]
b112524cd2 Keep single History observations visible and inspectable
A one-point stored History response drew no visible series and pointer inspection mapped it into a fictional one-millisecond window. Show a centred marker and one real timestamp, including measured zero, and share timestamp geometry with pointer inspection. Preserve multi-point rendering, keyboard access, empty states and request ownership.

Chromium and WebKit reproduce the predecessor defect. Twelve final desktop and phone states verify real canvas pixels, pointer and keyboard inspection, and sparse-to-empty refreshes. Synthetic presentation proof does not establish native collection or release availability.

Change-source: pulse-maintainer
2026-10-02 19:38:38 +01:00
pulse-triage[bot]
442717f409 Show disk temperature without extended SMART attributes
Treat optional SMART counters independently from a reported temperature. Preserve units, configured thresholds and the unavailable-details fallback. Cover live snapshot transitions and bind desktop/mobile browser proof.

Contract-Neutral: Existing disk-detail presentation bug fix; no shared frontend primitive, API, ownership, or entitlement boundary changes.
Change-source: pulse-maintainer
2026-10-02 17:37:38 +01:00
pulse-triage[bot]
c6edeee869 Distinguish empty History from failed background refreshes
Keep the last successful readings and source visible with an accessible warning until recovery or selection replacement. Stop promising future collection for empty history. Cover failure and recovery with request-state and two-engine browser controls.

Change-source: pulse-maintainer
2026-10-02 16:52:26 +01:00
pulse-triage[bot]
0be430813f Make storage History readings inspectable by keyboard
Add focus, bounded sample navigation and polite timestamp/value announcements without changing pointer or target ownership. Keep wrapped tooltip readings inside their box. Validate parent failure and final desktop/phone browser states.

Change-source: pulse-maintainer
2026-10-02 16:02:38 +01:00
pulse-triage[bot]
1177e4d143 Preserve History pointer inspection during matching live refreshes
Reset pointer state only when the selection changes, not on supplied sample updates. Add a mounted pointer-refresh regression and recheck delayed-target browser states.

Change-source: pulse-maintainer
2026-10-02 15:23:47 +01:00
pulse-triage[bot]
9dc6bd0ffe Keep shared History responses bound to the selected target
Invalidate superseded requests and polling, clear stale samples on selection changes, and exercise late completions in runtime and browser regressions.

Contract-Neutral: Correct request ownership in the existing shared chart without changing API, props, entitlements or public surface; dedicated runtime regressions accompany the repair.
Change-source: pulse-maintainer
2026-10-02 15:16:10 +01:00
pulse-triage[bot]
46d2727828 Validate final browser evidence without rewriting reviewed changes
Governance run 37016171545 rejected the original malformed timestamp even though a later reviewed receipt corrected it for identical runtime bytes. Use the existing fail-closed integration-range guard in CI while retaining per-commit canonical checks. Exercise the workflow shell with valid additive correction and invalid missing-base or unverified-content fixtures.

Change-source: pulse-maintainer
2026-10-02 15:04:12 +01:00
pulse-triage[bot]
ba36925af8 Correct storage browser receipt and shared-boundary documentation
The browser run already covered these exact runtime bytes. Correct its UTC timestamp and bind this receipt-only correction to its own parent. Document that missing capacity remains unavailable without changing shared row APIs or layout.

Change-source: pulse-maintainer
2026-10-02 13:59:26 +01:00
pulse-triage[bot]
60a6c933e0 Preserve missing capacity readings in storage pool details
Do not turn absent used capacity into an empty pool or invented free space.
Preserve independently observed bytes and explicit percentages, with guarded
derivation only from known inputs. Cover live drawer transitions and
desktop/phone browser states.

Contract-Neutral: Correct presentation of existing nullable capacity fields; no shared primitive API, layout, collector schema or recovery authority changes.
Change-source: pulse-maintainer
2026-10-02 13:58:40 +01:00
pulse-triage[bot]
811961243e Integrate reviewed bounded TrueNAS polling with live disk rows
Change-source: pulse-maintainer
2026-10-02 13:18:15 +01:00
pulse-triage[bot]
ffd7c9d993 Compose retained disk-row refresh repair with current main
Change-source: pulse-maintainer
2026-10-02 12:55:04 +01:00
rcourtman
8c538b5c2f
Remove the echo-only release joins and trim unused artifact retention (#2374)
Some checks are pending
Core E2E Tests / E2E verdict (push) Blocked by required conditions
Build and Test / Backend tests (api-0) (push) Blocked by required conditions
Build and Test / Secret Scan (push) Waiting to run
Build and Test / Detect changed areas (push) Waiting to run
Build and Test / Provider pair Docker acceptance (push) Blocked by required conditions
Build and Test / Frontend (push) Blocked by required conditions
Build and Test / Backend tests (rest-0) (push) Blocked by required conditions
Build and Test / Backend tests (api-1) (push) Blocked by required conditions
Build and Test / Benchmarks (push) Blocked by required conditions
Canonical Governance / governance (push) Waiting to run
Canonical Private Governance / private-governance (push) Waiting to run
Helm CI / Lint and Render Chart (push) Waiting to run
Public docs / check (push) Waiting to run
Core E2E Tests / Playwright Core E2E (shard 2/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 3/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 4/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 5/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 6/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 7/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 8/8) (push) Blocked by required conditions
Core E2E Tests / Validate E2E tier selection (push) Waiting to run
Core E2E Tests / Offline Organization provisioning (push) Waiting to run
Core E2E Tests / Playwright Core E2E (shard 1/8) (push) Blocked by required conditions
Core E2E Tests / Agent registration lifecycle (push) Waiting to run
Unified Agent Native Verification / Linux ARM64 (push) Waiting to run
Unified Agent Native Verification / Linux x64 (push) Waiting to run
Unified Agent Native Verification / Windows x64 (push) Waiting to run
Unified Agent Native Verification / macOS ARM64 (push) Waiting to run
Unified Agent Native Verification / macOS Intel (push) Waiting to run
Unified Agent Native Verification / FreeBSD cross-build contract (push) Waiting to run
First step of the release simplification plan. create-release.yml loses
candidate_qualification and release_readiness, which only restated other
jobs' results. Their exact predicates move into publish_release_tag,
publish_docker, publish_helm_chart, activate_release and
release_commit_verdict, with cancellation unchanged.
recover-release-activation accepts both run shapes, so v6.4.6 and older
runs recover exactly as before. Failure-only diagnostics and the chart
artifact nobody downloads keep 3 days instead of 14 or 90. Only lines
cut from main after this land use it (release/v6.6 from 7 Oct). Reviewed
with gpt-6.1-sol, SAFE TO MERGE; predicate equivalence sampled over
2,784 cases.
2026-10-02 12:50:52 +01:00
pulse-triage[bot]
a291579190 Keep timeout fixtures specific to the stalled RPC surface
The first snapshot control also stalled the unrelated app-stat stream. Model its valid empty reply and the proper stream field shapes in the two-connection poller fixture without weakening timeout, session, inventory or recovery assertions. Clarify that initial transport negotiation is bounded separately from each serialized RPC operation; runtime timeout policy is unchanged.

Contract-Neutral: Correct synthetic fixture responses and clarify the existing budget description; no runtime or wire behaviour changes.
Change-source: pulse-maintainer
2026-10-02 12:37:03 +01:00
pulse-triage[bot]
7e369d418f Bound TrueNAS RPC operations and keep polling after silent peers
Apply the configured timeout to serialized JSON-RPC operations, subscriptions and permitted read retries. Let cancelled waiters leave without dispatching or poisoning the active session. Preserve modern transport selection and action no-replay; distinguish caller deadlines from successful bounded log tails.

A required-method timeout must preserve cached host identity and previous success while allowing the next connection and recovery poll to proceed. Optional telemetry remains unavailable without blocking usable inventory. This repairs reproduced source paths, not a verified diagnosis or native resolution of issue #2382.

Change-source: pulse-maintainer
2026-10-02 12:27:35 +01:00
pulse-triage[bot]
6cf72e6d88 Compose reviewed alert diagnostics and setup guidance with upstream CI correction
Preserve every accepted commit while incorporating the published setup-node advisory-cache repair. Upstream changes a separate workflow; retain the proved runtime and documentation candidate bytes.

Change-source: pulse-maintainer
2026-10-02 12:05:07 +01:00
rcourtman
fc9d85c640 Pin setup-node caching off in the dependency advisory watch
The scheduled watch reads each release line's lockfile in the default
branch's cache scope, so it deliberately writes no dependency cache.
It sets no cache input, but the pinned setup-node enables npm caching
on its own once package.json names npm as its packageManager. Nothing
declares that today; adding it later would silently reopen a
default-branch cache write here. Set package-manager-cache: false, as
five release workflows already do, assert it in the workflow test, and
say how the contract's no-dependency-cache promise is kept.
2026-10-02 11:30:08 +01:00
pulse-triage[bot]
3d77bb5b3c Keep physical disk rows current across live snapshots
The keyed platform renderer preserves row owners, but the disk table captured mount-time presentation. Derive current health, readings, placement and target bindings reactively without discarding focus or expanded detail. Cover snapshot replacement, in-place updates, missing evidence and attention-filter recovery; record desktop and phone browser acceptance.

Change-source: pulse-maintainer
2026-10-02 11:17:00 +01:00
pulse-triage[bot]
1ce98f2693 Keep Apprise credentials and private payloads out of diagnostics
Suppress raw CLI targets/output, HTTP response bodies and credential-bearing endpoint paths across firing, recovery, tests, queue audits and settings logs. Preserve exact delivery inputs, typed causes and retry classification; retain structured status, counts and safe validation reasons.

Contract-Neutral: Shared agent-lifecycle and storage-recovery references are unchanged; this diagnostic repair alters no agent or storage behaviour, API schema, destination admission or delivery policy.
Change-source: pulse-maintainer
2026-10-02 03:34:36 +01:00
pulse-triage[bot]
45eec9a20e Keep native TrueNAS Thermals in local and persisted host History
Finish the connected #2077 outcome: persist an observed TrueNAS host temperature through the existing canonical writer, so local chart coverage cannot suppress the Thermals panel. Extend the pinned REST-to-chart control to cover the write, persistent readback and full local-window fast path; preserve source and absence gates.

Change-source: pulse-maintainer
Contract-Neutral: Restores existing TrueNAS Thermals history through its canonical writer; no agent lifecycle, schema, route, resource identity or alert-policy delta.
2026-10-02 02:09:48 +01:00
pulse-triage[bot]
579eee2907 Preserve independent ARC and stop cancelled CORE reporting before I/O
Complete the native CORE #2077 repair after its whole-suite adverse result: retain ARC without inventing free RAM, enforce live-window freshness even with coarse RRD steps, and assert bounded graph splitting including CPU temperature. Keep empty/zero, aligned ARC and transport boundaries intact.

Change-source: pulse-maintainer
2026-10-02 01:49:25 +01:00
pulse-triage[bot]
bab5cf77d6 Prove native CORE catalogue overflow fails without partial totals
Exercise the unique-device selection ceiling separately from deduplication, and keep the graph-isolation account aligned with catalogue-selected requests. No runtime logic or public contract shape is changed.

Change-source: pulse-maintainer
2026-10-02 00:48:46 +01:00
pulse-triage[bot]
c78840e371 Classify the native CORE reporting fixture for canonical verification
Bind the anonymised JSON regression input to the existing TrueNAS runtime proof policy. The repair restores existing canonical behavior and has no public contract shape change; its source, tests and substantive monitoring account remain in the preceding commit.

Change-source: pulse-maintainer
2026-10-02 00:32:55 +01:00
pulse-triage[bot]
b50313c599 Decode native CORE reporting rows across live metrics and History
Use external RRD timing, native legends, scoped device graphs and measured CPU temperature for issue #2077. Keep absent, empty and zero buckets distinct, normalize CORE CPU states and preserve ARC alignment, safe transport failures and canonical projection. Add native-shape and end-to-end monitoring controls without changing release selection.

Change-source: pulse-maintainer
Contract-Neutral: Restores existing canonical metrics and temperature behaviour for CORE input formats; no public schema, route, resource identity or alert-policy delta.
2026-10-02 00:32:32 +01:00
pulse-triage[bot]
c3f627d0d6 Keep monitor bootstrap verification in canonical order
Move the quiet-hours startup regression beside the other monitor proof files without changing any runtime, test or contract content. This corrects the registry audit's lexical ordering error.

Change-source: pulse-maintainer
2026-10-01 23:10:43 +01:00
pulse-triage[bot]
5213b794b2 Revalidate queued alert delivery against current quiet hours
Keep continuous and late replay held without spending a provider attempt. Split mixed batches atomically so eligible alerts retain admitted destinations, occurrence links and retry budgets, and bind saved monitor policy before activating persisted work. Add local receipt, cancellation, rollback, reconstruction and race regression coverage with the owning contracts and verification routes.

Change-source: pulse-maintainer
2026-10-01 23:05:07 +01:00
pulse-triage[bot]
0834ec0e14 Keep quiet-hours verification paths in canonical order
Repair the deterministic registry audit rejection by moving the dedicated quiet-hours test into its lexicographic position and matching the existing indentation. Preserve all verification entries, path policies and runtime bytes.

Change-source: pulse-maintainer
2026-10-01 21:54:09 +01:00
courtmanr@gmail.com
6ce41ae9d4 Fold the echo-only release joins into their public writers
candidate_qualification and release_readiness only restated other jobs'
results. publish_release_tag, publish_docker, publish_helm_chart and
activate_release now each carry the exact candidate predicate in their own
needs and if, guarded by !cancelled() with the same allowed integration
skip, and activation joins the tag and both registry publications directly.
The commit verdict restates every candidate result in place of the
readiness join.

recover-release-activation.yml accepts both shapes. A source run that has
release_readiness still has to prove only that join, as before. A run
without it has to prove publish_release_tag and at least one, and only
successful, jobs under the publish_docker and publish_helm_chart caller IDs.

Failure diagnostics and the inspection-only Helm chart artifact, which
nothing downloads, are kept for three days instead of 14 and 90.
2026-10-01 21:47:58 +01:00
pulse-triage[bot]
cecbd5418b Respect local clocks through alert quiet-hours changes
Compare scheduled civil minutes on each selected day so repeated or missing DST minutes cannot shift suppression. Calculate non-full-day replay from real clock boundaries and keep location fallback read-only for concurrent policy consumers. Retain category controls and the existing full-day replay boundary; pin the civil-time contract and dedicated regression proof.

Change-source: pulse-maintainer
2026-10-01 21:11:11 +01:00
pulse-triage[bot]
efb6fb742b Integrate reviewed RAID spare-count repair
Preserve exact Core candidate identity for issue #2369, its required-member provenance and genuine-deficit controls. Retain source proof limitations and the owned compatible patch route; no frontend content changes.

Change-source: pulse-maintainer
2026-10-01 20:36:29 +01:00
pulse-triage[bot]
f99803f46d Integrate reviewed Docs accessibility and guidance repair
Change-source: pulse-maintainer
2026-10-01 20:00:13 +01:00
pulse-triage[bot]
14d3dc3b6c Fix MD RAID spare counts without hiding member failures
Retain configured RAID members separately from source-native totals through collection, reports and canonical read views. Correct the healthy legacy mdadm tuple from #2369 without subtracting spares from mdstat requirements or suppressing real deficits, failures and recovery warnings. Preserve observed zero-active counts through fallback, and verify collector, wire, ingestion, health and canonical activation/resolution boundaries.

Change-source: pulse-maintainer
2026-10-01 19:56:47 +01:00
pulse-triage[bot]
04d12bc16e Restore semantic column headers in shipped documentation tables
Extract the Windows-independent Docs repair from candidate 136d039de4a1f8f7debfb1f82d4fffd8bf610083. Add trusted scope after sanitization without expanding document-controlled attributes. Preserve table-local scrolling and verify the current eight-header plans table in desktop Chromium and phone WebKit; native Windows work remains separate.

Change-source: pulse-maintainer
2026-10-01 19:27:17 +01:00
pulse-triage[bot]
2ae06bb2f3 Compose retained Docker update restart repair for exact proof
Preserve assigned main maintenance while completing the retained alert lifecycle validation.

Change-source: pulse-maintainer
2026-10-01 18:26:13 +01:00
pulse-triage[bot]
bb1903e48d Stop demo diagnostics at failed tailnet readiness
Failed setup now yields local-only, topology-free diagnostics. Require recognised Running state and successful tailnet ping before TCP, retain probe exits without raw private output or fallback probes, and exercise twenty synthetic readiness/privacy cases. Parent controls expose false success and private output on both channels. Keep workflow identities, secrets, action pins, mutation gates and release scope unchanged.

Change-source: pulse-maintainer
2026-10-01 17:36:26 +01:00
pulse-triage[bot]
ed8415ea6a Keep active Docker update age through restart
A restored image-update incident must not wait another whole delay before positive reports refresh it. Recover pending age from the same resource's active occurrence, retaining acknowledgement and delivery identity while preserving explicit recovery and a new update's normal delay. Exercise both checkpoint authorities, both cleanup paths, cached and unknown evidence, 24/48-hour delays and isolated hosts through the public checker.

Change-source: pulse-maintainer
2026-10-01 16:58:21 +01:00
pulse-triage[bot]
858abc579a Integrate reviewed listener-owned health and telemetry transition repair
Change-source: pulse-maintainer
2026-10-01 16:28:26 +01:00
pulse-triage[bot]
b21f086e85 Keep Unix lifecycle credentials out of copied commands
Replace literal credential bootstraps with the exercised bounded Core private-entry pattern, preserve a checked local private-file route for non-terminal FreeBSD command fields, and consolidate Unix repair, upgrade and removal transport without changing token issuance, TLS choice or host identity. Removal does not depend on a new binary preflight. Windows credential transport remains the next rework step. Add executable PTY/file/lifecycle proofs and the missing DOMPurify after-attributes detached-subtree regression, with parent-bound browser evidence.

Change-source: pulse-maintainer
2026-10-01 14:07:33 +01:00
pulse-triage[bot]
33345f2981 Preserve telemetry sender transitions and bound-socket health
Adapt PR2351 to current main without losing bounded probe deadlines, retries, explicit binds or confidentiality. Inspect IPv6 wildcard socket mode so unrelated servers sharing the port cannot determine Pulse health. Apply the telemetry callback only after a persisted explicit boolean transition, including stale-disk and null-input boundaries.

Retain real HTTP/HTTPS wildcard and same-port isolation regressions, callback persistence-order tests, and the owning subsystem contracts. No dependency manifests, frontend source or telemetry payload schema change. Exact runtime proof remains dependent on the unavailable root graph; it is not represented as passed.

Change-source: pulse-maintainer
Original-source: https://github.com/rcourtman/Pulse/pull/2351
Original-commit: f50c4d6e3b
Co-authored-by: rcourtman <8825017+rcourtman@users.noreply.github.com>
2026-10-01 13:28:21 +01:00
pulse-triage[bot]
9189a7262e Integrate reviewed manual-version auto-update consent repair
Change-source: pulse-maintainer
2026-10-01 13:01:48 +01:00
pulse-triage[bot]
48b22f9412 Integrate reviewed connected-dashboard broadcast allocation repair
Preserve exact Core candidate c0525852f8 and its differential, affected-race and benchmark evidence. Compose with the fixed initial main frontier; installed CPU and release follow-through remain separately owned.

Change-source: pulse-maintainer
2026-10-01 12:55:46 +01:00
pulse-triage[bot]
c0525852f8 Avoid discarded identity candidates in live broadcast projections
The residual whole-broadcast profile attributes about 80 percent of synthetic allocation to connected-infrastructure grouping. Request only its unchanged 0.90 identity floor, and discard equal or worse-priority fallback peers before allocating and sorting them. Keep general matching and all group identity, ambiguity, explanation and review semantics against independent pre-repair oracles. Update the obsolete broadcast-wrapper source assertion to the prepared single-pass path.

Change-source: pulse-maintainer
2026-10-01 12:18:28 +01:00
pulse-triage[bot]
b281ee80e1 Reconcile initial main frontier with reviewed local maintenance
Change-source: pulse-maintainer
2026-10-01 12:15:01 +01:00
rcourtman
4eeb297ca6
Watch main and every active release line for new frontend advisories daily (#2366)
Some checks are pending
Build and Test / Backend tests (rest-1) (push) Blocked by required conditions
Build and Test / Backend tests (api-0) (push) Blocked by required conditions
Build and Test / Backend tests (api-1) (push) Blocked by required conditions
Build and Test / Backend tests (api-2) (push) Blocked by required conditions
Build and Test / Backend tests (api-3) (push) Blocked by required conditions
Build and Test / Backend tests (api-4) (push) Blocked by required conditions
Build and Test / Backend tests (api) (push) Blocked by required conditions
Build and Test / Script smoke tests & backend build (push) Blocked by required conditions
Build and Test / Benchmarks (push) Blocked by required conditions
Canonical Governance / governance (push) Waiting to run
Canonical Private Governance / private-governance (push) Waiting to run
Public docs / check (push) Waiting to run
Core E2E Tests / Validate E2E tier selection (push) Waiting to run
Core E2E Tests / Offline Organization provisioning (push) Waiting to run
Core E2E Tests / Playwright Core E2E (shard 1/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 2/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 3/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 4/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 5/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 6/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 7/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 8/8) (push) Blocked by required conditions
Core E2E Tests / Agent registration lifecycle (push) Waiting to run
Core E2E Tests / E2E verdict (push) Blocked by required conditions
Unified Agent Native Verification / Linux ARM64 (push) Waiting to run
Unified Agent Native Verification / Linux x64 (push) Waiting to run
Unified Agent Native Verification / Windows x64 (push) Waiting to run
Unified Agent Native Verification / macOS ARM64 (push) Waiting to run
Unified Agent Native Verification / macOS Intel (push) Waiting to run
Unified Agent Native Verification / FreeBSD cross-build contract (push) Waiting to run
On 30 Sep and 1 Oct two new advisories (brace-expansion
GHSA-q2hr-2g5m-vwhr, DOMPurify GHSA-p98j-92pf-mc4p) failed the required
frontend audit on every PR across main, release/v6.4 and release/v6.5,
holding the v6.5 RC for days and blocking the v6.4.6 preparation. The
existing scheduled npm-audit is informational and only sees main. This
adds a daily workflow that runs the same complete frontend audit as
Build and Test on main and every active release line, fails on any
finding, and names the branch, advisories and fix. The maintainer's
release-path health check raises it to Delivery immediately.
2026-10-01 12:01:43 +01:00
pulse-triage[bot]
36200e07db Use canonical resource fields in broadcast regression fixtures
The first exact candidate proof compiled and passed frontend snapshot tests, but rejected two monitoring fixture fields that only exist on frontend projections. Use the canonical resource name and tags to test the same sort/freshness boundaries. Preserve that failed aggregate result; no production code or expectation is relaxed.

Change-source: pulse-maintainer
2026-10-01 11:50:43 +01:00
pulse-triage[bot]
eb7e70135d Preserve auto-update consent during manual version changes
An update, rollback or reinstall must not silently enable unattended updates. Share the existing-install opt-in prompt and retain affirmative CLI and interactive choices without changing helper refresh or fresh-install defaults.

Exercise all five existing main flows and add bounded configuration/timer intent observations to the signed published lifecycle rehearsal, including changed and unavailable negative controls.

Change-source: pulse-maintainer
2026-10-01 11:50:33 +01:00
courtmanr@gmail.com
64d8dbc7fc Watch main and active release lines daily for new npm advisories
On 30 Sep-1 Oct 2026 GHSA-q2hr-2g5m-vwhr (brace-expansion) and
GHSA-p98j-92pf-mc4p (DOMPurify) failed the required "Audit complete
frontend dependency graph" step on every pull request to main,
release/v6.4 and release/v6.5. That held the v6.4.6 preparation PR and
the v6.5 RC for days with no owner. The scheduled audit in
security-scan.yml only informs and runs on the default branch, so
release lines were never checked.

dependency-advisory-watch.yml runs daily and on dispatch. It lists main
plus every release/v<major>.<minor> line at or newer than the latest
stable's line (all lines if that lookup fails), then audits each in a
fail-fast-free matrix. Each job fetches only that line's
frontend-modern/package.json and package-lock.json with git and runs
scripts/npm-audit-retry.sh all on them under the same Node.js pin that
build-and-test requires. npm audit reads the lockfile, so nothing is
installed. The job never checks out or runs the audited branch's code,
because a scheduled run holds the default branch's cache scope and
CodeQL flagged running npm ci there as cache poisoning.

A job fails when the audit fails, and its step summary and annotation
name the branch, the GHSA ids and the fix (npm audit fix
--package-lock-only plus raised floors in dependencySecurity.test.ts).
Read-only, hosted-only, no secrets, no uploads.
2026-10-01 11:46:12 +01:00
pulse-triage[bot]
4b01e25cdf Remove redundant connected-dashboard projection and snapshot copies
List the continuity-aware registry once, decorate one owned host projection, and sort final frontend rows rather than a second estate-sized conversion array. Encode concrete frontend resources directly into immutable snapshot buffers, decoding every authoritative ID from those bytes; leave generic marshalers and all other fields on the existing path. Keep live freshness, alert and lifecycle semantics without a cache.

Change-source: pulse-maintainer
2026-10-01 11:32:30 +01:00
pulse-triage[bot]
fee838d4e4 Integrate reviewed credential-safe container diagnostics
Preserve both exact Core candidate commits; keep private terminal entry and monitoring trust boundaries intact.

Change-source: pulse-maintainer
2026-10-01 11:13:35 +01:00
pulse-triage[bot]
f047d7b5db Reconcile published lifecycle rehearsal with reviewed maintenance
Preserve the complete reviewed maintenance tip and published upstream source unchanged. Combine their installability contract and subsystem registry entries without changing runtime behaviour.

Change-source: pulse-maintainer
2026-10-01 10:10:22 +01:00
pulse-triage[bot]
166f6d8aae Keep container diagnostics bootstrap credentials out of copied commands
Reuse the complete-download and preflight private-token entry boundary for both monitoring modes. Keep issued credentials separate and no-store, use the installer-owned token path in the diagnostic service reference, and reject structural unit injection before minting. Add executable root/sudo, history, transport, failure cleanup and systemd grammar regressions alongside the subsystem contracts.

Change-source: pulse-maintainer
2026-10-01 09:22:15 +01:00